Mati Ferreira

19.6K posts

Mati Ferreira banner
Mati Ferreira

Mati Ferreira

@MEFA__

Responding to my curiosity. Open mind. Open heart. Open will. ☀

Colorado Katılım Mayıs 2009
3.3K Takip Edilen843 Takipçiler
Sabitlenmiş Tweet
Mati Ferreira
Mati Ferreira@MEFA__·
Hilo eterno de música.
Español
4
0
7
0
Mati Ferreira
Mati Ferreira@MEFA__·
Hilo eterno de música.
Español
4
0
7
0
Mati Ferreira
Mati Ferreira@MEFA__·
@karpathy TIL that it is not smart to always use the latest version available.
English
0
0
0
10
Andrej Karpathy
Andrej Karpathy@karpathy·
Software horror: litellm PyPI supply chain attack. Simple `pip install litellm` was enough to exfiltrate SSH keys, AWS/GCP/Azure creds, Kubernetes configs, git credentials, env vars (all your API keys), shell history, crypto wallets, SSL private keys, CI/CD secrets, database passwords. LiteLLM itself has 97 million downloads per month which is already terrible, but much worse, the contagion spreads to any project that depends on litellm. For example, if you did `pip install dspy` (which depended on litellm>=1.64.0), you'd also be pwnd. Same for any other large project that depended on litellm. Afaict the poisoned version was up for only less than ~1 hour. The attack had a bug which led to its discovery - Callum McMahon was using an MCP plugin inside Cursor that pulled in litellm as a transitive dependency. When litellm 1.82.8 installed, their machine ran out of RAM and crashed. So if the attacker didn't vibe code this attack it could have been undetected for many days or weeks. Supply chain attacks like this are basically the scariest thing imaginable in modern software. Every time you install any depedency you could be pulling in a poisoned package anywhere deep inside its entire depedency tree. This is especially risky with large projects that might have lots and lots of dependencies. The credentials that do get stolen in each attack can then be used to take over more accounts and compromise more packages. Classical software engineering would have you believe that dependencies are good (we're building pyramids from bricks), but imo this has to be re-evaluated, and it's why I've been so growingly averse to them, preferring to use LLMs to "yoink" functionality when it's simple enough and possible.
Daniel Hnyk@hnykda

LiteLLM HAS BEEN COMPROMISED, DO NOT UPDATE. We just discovered that LiteLLM pypi release 1.82.8. It has been compromised, it contains litellm_init.pth with base64 encoded instructions to send all the credentials it can find to remote server + self-replicate. link below

English
1.3K
5.4K
27.8K
65.2M
Mati Ferreira
Mati Ferreira@MEFA__·
@Ale_PPathways @K8050906068853 You don't get to decide what people make chaos about. So don't say it was "for nothing". You clearly did something that put people off. Own it, apologize and learn.
English
0
0
7
232
Alessandro Calvo
Alessandro Calvo@Ale_PPathways·
I deleted it because it has raised chaos for nothing, it came through differently than what it was intended to be. I understand it can have created confusion because I expressed myself in a way that was indeed easy to misenterpret. That was not my intention, so I wouldn't leave there a post that can be misleading.
English
7
0
1
7.6K
Alessandro Calvo
Alessandro Calvo@Ale_PPathways·
Some people spreaded random fuss about the Geingo Night being somewhat related to "sexual tourism". I want to make extremely clear that it is absolutely something we reject. It is a moment of socialization among expats and among expats and locals. Everything else never came out of our mouth or our content. It is correct to state that most of the local list is comprised of girls and most of the expat list is comprised of men. That is free market, nothing else. 90% of foreigners in Asuncion are single men, so no surprise there. And that seems to have called the attention of many Paraguayan ladies would like to hang out practice their English or just try out a different format of party in Asu. We strongly disagree with the false accusations of promoting sexual tourism or anything even close to it. Come enjoy the food, the drinks, the chats and the music instead of throwing random hate. Peace ✌️
English
101
7
71
65.1K
Mati Ferreira retweetledi
martín
martín@marrchino·
Hoy en cuidando tu bolsillo: encontré un lugar en el mercado 4 que es el mundo de las americanas, almohadas, toallas, sábanas hoteleras, todo lo que puedas imaginar 100% algodón y los precios regalados. No vas a creer. Hay combos, ejemplo: 1 funda de cama 1 cubre cama, 2 fundas para almohadas a 120mil!! Hay más.
Español
17
115
1K
68.6K
Mati Ferreira
Mati Ferreira@MEFA__·
@paulg He can choose what questions to answer. Easy work I would say.
English
0
0
0
7
Mati Ferreira
Mati Ferreira@MEFA__·
Peter Senge: “If AI exists to assist humans, everything it does subtly reinforces the human-centrism that, ironically, is destroying modern human society". Food for thought.
English
0
0
0
20
Mati Ferreira retweetledi
carl feynman
carl feynman@carl_feynman·
My dad (Richard Feynman) had a side hustle doing industrial consulting. He'd spend a few hours visiting a company, talking to the engineers, looking at stuff, and then maybe have a good suggestion. Sometimes he would bring his son along. I only recall one of his suggestions, but it made the company he was consulting for way better off, so I guess his exorbitant consulting fees were worth it. We could have been wealthier if he had done it systematically, but he didn't want to be organized about looking for jobs, so it just happened when someone asked.
Nucleonics 𓋍 Simulator@EtherDais

We need more mercenary polymaths

English
290
1.5K
24.1K
2.5M
Michelle Fang 🌁
Michelle Fang 🌁@michelleefang·
if you're vibe coding or building over the holidays, i want to gift one of you a 6 month subscription of claude pro to support <3 just drop a comment below. merry christmas!
English
7.5K
189
9K
1.1M